
FortinetNSE 6 - FortiSIEM Analyst
Domain 1Objective 2
Apply Group by and Data Aggregation on Search Results NSE6-FORTISIEM-ANALYST Practice Questions (Page 2)
Part of the Analytics domain, which makes up ~18% of our current practice bank. Fortinet does not publish an official question count, but from its 70-minute exam (~30–45 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
2concepts
Questions 6–10
- 6
In a FortiSIEM aggregation query, which function returns the number of distinct values for a specified field?
Select an answer first - 7
A SOC manager wants a report showing the average duration of all active directory lockout events per domain controller over the past week. The events have fields `dcName` and `lockDuration` (in seconds). Which aggregation should be applied to the `lockDuration` field when grouping by `dcName`?
Select an answer first - 8
An analyst is creating a dashboard widget that shows the total bytes transferred per protocol (HTTP, HTTPS, FTP) for the current month. The events contain `protocol` and `bytesSent`. Which GROUP BY and aggregation combination produces the required output?
Select an answer first - 9
A large enterprise generates millions of authentication events per day. An analyst needs a report of the top 10 users by failed login count, but the raw event volume makes the query slow. The analyst notices that the `user` field has high cardinality. Which approach best balances accuracy and query performance?
Select an answer first - 10
A SOC analyst needs to know how many distinct malware families have been detected on each host in the last week. The events contain `hostName` and `malwareFamily`. Which aggregation should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISIEM-ANALYST” is a trademark of its owner, used for identification only.